accuranker
Warn
Audited by Socket on Mar 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This SKILL.md is a benign integration guide that instructs an agent to use the official Membrane CLI to access Accuranker API functionality. It does not request unnecessary credentials, does not contain direct exfiltration code, and explicitly recommends letting Membrane manage authentication. The main supply-chain concern is the normal risk of installing a third-party CLI from npm (validate the package owner and version). Overall risk is low but depends on trusting the Membrane service and the npm package integrity.
Confidence: 80%Severity: 75%
Audit Metadata